Skip to content
Scope, price and timeline published on every engagement page Engineers assigned within 3 working days of kickoff Your repositories, cloud accounts and licences stay in your name

Cloud IAM Permissions Audit

Every identity in your cloud account reviewed against what it actually uses, with over-permissioned roles tightened safely.

Delivered in

10 working days

Revisions

One round, included

Ownership

Yours from day one

Overview

What this engagement is

Permissions accumulate. A developer needed production access for one incident in 2023 and still has it. A CI role was given administrator rights because the correct policy was fiddly to work out. We pull the access analyser and CloudTrail data, compare granted permissions against what each identity has actually used over 90 days, and write least-privilege policies to replace the broad ones. Nothing is tightened blindly: every change is proposed, reviewed with you, and applied where it will not break a working system.

Deliverables

What lands in your repositories

7 items
  • Inventory of every user, role, service account and access key
  • Used-versus-granted comparison over 90 days of activity data
  • Least-privilege policy recommendations written and ready to apply
  • Unused credential and stale identity list with a removal plan
  • Multi-factor authentication and root account configuration review
  • Cross-account trust and external access review
  • Quarterly access review process documented for your team

Outcomes

What changes once it ships

A compromised key gives an attacker far less than it does today

Departed staff and dormant credentials are found and removed

A repeatable quarterly review your team can run without us

Process

How the 4 stages run

  1. 01

    Collect

    identity inventory and activity logs are gathered and analysed

  2. 02

    Compare

    granted permissions measured against real usage per identity

  3. 03

    Propose

    tightened policies drafted and reviewed with the owning teams

  4. 04

    Apply

    changes rolled out in agreed batches with rollback ready

Booked most often by

  • Cloud accounts where permissions have grown for years without review
  • Companies where former staff may still have valid access
  • Teams preparing for an audit that asks about least privilege

What we need from you

  • Read-only security audit access to the cloud accounts in scope
  • Confirmation of who currently owns each service account
  • A change window for applying the agreed policy updates

These are collected in the technical brief that opens in your dashboard the moment payment clears. The clock starts when they arrive, not before.

Answers

Questions this engagement raises

That is why we use 90 days of real usage data and roll out in batches. Anything ambiguous is flagged rather than guessed at.

Yes, with the equivalent identity services. Mention your provider at checkout.

Only with your written approval, batch by batch. Nothing is revoked unilaterally.

This is engineering work, not a physical product — nothing ships and there is no stock to run out of. Delivery is to the working days stated above, into systems you control, and the refund terms set out what happens if we miss the date.

Booked alongside

Engagements that pair with this one

All Security & Compliance

Web Application VAPT

A manual penetration test of your web application with proof-of-concept evidence and a retest after you fix.

Manual penetration test covering authentication, authorisation and business logic
12 working days Scope published

Fixed fee · GST incl.

₹29,999

SOC 2 Evidence Groundwork

The technical controls and evidence collection an SOC 2 Type II audit needs, set up before the observation window starts.

Control gap assessment against the Trust Services Criteria you are scoping
30 working days Scope published

Fixed fee · GST incl.

₹44,999

GST included

₹18,999

Capacity open this month

Read the scope. Know the price. Start on Monday.

No discovery calls to find out a number, no statements of work that take three weeks to sign. Pick the engagement that matches the problem and we assign the engineers.